---
title: "Create a ServiceNow bulk/dynamic share for Splunk"
canonical: "https://docs.perspectium.com/space/Iodine/1705075/Create%20a%20ServiceNow%20bulk%2Fdynamic%20share%20for%20Splunk"
format: markdown
---
To enable the sharing of ITSM data from your ServiceNow instance to your Splunk instance, you will need to create a ServiceNow bulk share and/or a ServiceNow dynamic share. A ServiceNow bulk share is a one-time transfer of data from your ServiceNow instance. A ServiceNow dynamic share allows for real time sharing of ServiceNow records as they are created, updated, and deleted. Creating a bulk share and/or dynamic share will share out your ServiceNow data immediately as well as share out subsequent data that is collected as ServiceNow records are created, updated, and deleted.

:info: **<u>NOTE</u>**: Like other DataSync targets, ServiceNow fields that have [display values](https://docs.servicenow.com/bundle/orlando-platform-administration/page/administer/field-administration/concept/c_DisplayValues.html) will save with the sys_id as the field's value in Splunk. To also share the display values, [turn on the DataSync display value property](https://docs-perspectium.atlassian.net/wiki/display/iodine/DataSync+Settings#DataSyncSettings-Sharedisplayvaluesforreferencefieldsandchoicelists).

## **Prerequisites**

---

:warning: You will first need to [install the Perspectium Core update set](https://docs-perspectium.atlassian.net/wiki/display/iodine/Install+and+Configure+DataSync+for+ServiceNow). You can request a download link for this update set by contacting [Perspectium Support](mailto:support@perspectium.com).

:warning: You will also need to [create a ServiceNow shared queue](https://docs-perspectium.atlassian.net/wiki/display/iodine/ServiceNow+shared+and+subscribed+queues#ServiceNowsharedandsubscribedqueues-CreateaServiceNowsharedqueue) that points to your Splunk instance. This queue should have been created by [Perspectium Support](mailto:support@perspectium.com) upon initial configuration of your ServiceNow instance.


## **Procedure**

To create a bulk/dynamic share for your ServiceNow-to-Splunk integration, follow these steps:

---

> Macro (ui-steps)
> 
> > Macro (legacy-content)
> 
> > Macro (legacy-content)

OR

> Macro (ui-steps)
> 
> > Macro (legacy-content)
> 
> > Macro (legacy-content)

**Next steps**

---

[Open your Splunk HTTP Event Collector port to the Perspectium Integration Mesh](https://docs-perspectium.atlassian.net/wiki/spaces/Iodine/pages/1705077)